Apparently this MChap vulnerability has been around awhile. It's been broken 
for some time, just wasn't practical to break the hash. What Moxie did was add 
the ability to bust the hash in the cloud making it faster and easier. In a 
PPTP situation grabbing that mchap hash enroute is not easily done. The risk is 
there (always has been) and PPTP users should move away as soon as practical, 
PPTP is legacy and now less secure than ever. But no need to panic about this 
one, imho.

Wireless MChap2 folks should make their clients validate the radius server cert 
before passing the hash.

Disclaimer:  The above is paraphrasing my source who was at Moxies talk on this 
at Defcon.
________________________________________
From: Ben Scott [[email protected]]
Sent: Tuesday, July 31, 2012 11:51 AM
To: NT System Admin Issues
Subject: Re: MSCHAP V2 completely broken

On Tue, Jul 31, 2012 at 11:40 AM, Matthew W. Ross
<[email protected]> wrote:
> I don't follow the crypto world, so is there an alternative crypto for PPTP 
> available? Just curious.

  It's not so much PPTP as Microsoft's various attempts at
authentication/key exchange methods that are broken.  But for VPNs,
the rest of the world seems to have gone in the direction of IPsec-
and SSL-based solutions.  OpenVPN is SSL-based, and Win 2000 and later
support an IPsec-based VPN.

  This is prolly more significant for places that are using MS-CHAP
for wireless/network authentication.

-- Ben

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

---
To manage subscriptions click here: 
http://lyris.sunbelt-software.com/read/my_forums/
or send an email to [email protected]
with the body: unsubscribe ntsysadmin

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

---
To manage subscriptions click here: 
http://lyris.sunbelt-software.com/read/my_forums/
or send an email to [email protected]
with the body: unsubscribe ntsysadmin

Reply via email to